Cybersecurity Foundations & Ethics
A fictional regional manufacturer, Carrollton Precision Works, is standing up its first security team. You are the newest hire and must set up the training lab safely before anyone touches a tool.
- Define CIA, AAA, least privilege, defense-in-depth and zero trust
- State the legal and ethical limits of security testing
- Build and label an isolated lab LAN
- Threats vs. vulnerabilities vs. risk
- Policies, standards and baselines
- Career pathways
- Professional ethics
Four-mode learning matrix
Build and label a small isolated lab LAN; inventory every asset.
Lab 1 — Launch, stop, inspect and reset a guided workstation container.
OSI / network orientation walkthrough. Role: Help-desk technician.
No headset? Guided slideshow + printed OSI map. Printed and mobile versions are also available.
Write your personal lab safety & authorization statement.
Draft a one-page team charter and lab ground rules.
- Managed switch or small router
- Patch cables
- Lab workstation
- Docker Desktop / Engine + Compose
- Text editor
Every security role begins with written authorization and an accurate asset inventory — you can't protect what you haven't listed.
Bring up student-ws, stop it, inspect it, then reset the range and confirm a clean state.
Verify ot-control is reachable only via idmz; document the path and the block.
Test each ACL rule for allow and deny; record the evidence pair.
Trace the pivot from webapp → jump → historian → plc-sim; build the timeline.
Restore from snapshot, apply remediation, and re-run steps 4, 12 and 15 to prove closure.